OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-88362

HIGH · CVSS 7.5 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

A vulnerability exists in the Java implementation of MuJS, where improper numeric conversion in the jsR_isindex() function can lead to out-of-range floating-point values being incorrectly converted to integers. This flaw can be exploited through specially crafted JavaScript input, potentially resulting in undefined behavior and process termination, which may lead to a denial of service. Organizations utilizing Java applications that incorporate MuJS should prioritize addressing this issue to mitigate the risk of service disruption.

CVE
CVE-2026-88362
Severity
HIGH
CVSS
7.5
EPSS
0.34%
Java

Original NVD Description

MuJS e892c9fdb contains an incorrect numeric conversion vulnerability in jsR_isindex() in jsrun.c. A specially crafted JavaScript input containing an excessively large numeric array index can cause an out-of-range floating-point value to be converted to an integer without proper range validation. This results in undefined behavior and can cause process termination, leading to denial of service.